PT-2026-99182 · Openclaw · Openclaw

CVE-2026-100545

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

6.0

Medium

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openclaw versions prior to 2026.8.1
Description Incorrect enforcement of sender tool policies occurs during session-memory filename generation. The process creates an embedded helper that retains tools previously removed by the originating sender's policy. If session-memory filename generation is enabled for an agent accessible to lower-trust senders, model-mediated instructions can trigger the helper to invoke tools that exceed the sender's effective policy, potentially resulting in the creation of persistent scheduled work.
Recommendations Update to version 2026.8.1. Disable session-memory filename generation for agents reachable by lower-trust senders.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100545
GHSA-5FWV-RRVP-8XVR

Affected Products

Openclaw